Evaluating the privacy of Android mobile applications under forensic analysis

被引:20
|
作者
Ntantogian, Christoforos [1 ]
Apostolopoulos, Dimitris [1 ]
Marinakis, Giannis [1 ]
Xenakis, Christos [1 ]
机构
[1] Univ Piraeus, Dept Digital Syst, Piraeus, Greece
关键词
Privacy of mobile applications; Mobile forensics; Android; Memory dump; Mobile applications; Volatile memory; Authentication credentials;
D O I
10.1016/j.cose.2014.01.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we investigate and evaluate through experimental analysis the possibility of recovering authentication credentials of mobile applications from the volatile memory of Android mobile devices. Throughout the carried experiments and analysis, we have, exclusively, used open-source and free forensic tools. Overall, the contribution of this paper is threefold. First, it thoroughly, examines thirteen (13) mobile applications, which represent four common application categories that elaborate sensitive users' data, whether it is possible to recover authentication credentials from the physical memory of mobile devices, following thirty (30) different scenarios. Second, it explores in the considered applications, if we can discover patterns and expressions that indicate the exact position of authentication credentials in a memory dump. Third, it reveals a set of critical observations regarding the privacy of Android mobile applications and devices. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:66 / 76
页数:11
相关论文
共 50 条
  • [31] Privacy Consistency Analyzer for Android Applications
    Maitra, Sayan
    Suh, Bohyun
    Ghanavati, Sepideh
    2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 28 - 33
  • [32] Evaluating the Understandability of Android Applications
    Saifan, Ahmad A.
    Alsghaier, Hiba
    Alkhateeb, Khaled
    INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2018, 6 (01) : 44 - 57
  • [33] Methodologies and Forensic Analysis Tools on Android Mobile Devices: A Systematic Literature Review
    Cristian, Pozo-Calderon
    Hernan, Tones-Carrion
    Rene, Guaman-Quinche
    Francisco, Alvarez-Pineda
    Cristian, Narvaez-Guillen
    2020 15TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2020), 2020,
  • [34] Network and device forensic analysis of Android social-messaging applications
    Walnycky, Daniel
    Baggili, Ibrahim
    Marrington, Andrew
    Moore, Jason
    Breitinger, Frank
    DIGITAL INVESTIGATION, 2015, 14 : S77 - S84
  • [35] Forensic analysis of social networking applications on mobile devices
    Al Mutawa, Noora
    Baggili, Ibrahim
    Marrington, Andrew
    DIGITAL INVESTIGATION, 2012, 9 : S24 - S33
  • [36] Digital forensic analysis of mobile automotive maintenance applications
    Sumaila, Faisal
    Bahsi, Hayretdin
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2022, 43
  • [37] COMBINATION ATTACK OF ANDROID APPLICATIONS ANALYSIS SCHEME BASED ON PRIVACY LEAK
    Gu, Jieming
    Li, Chengze
    Lei, Dian
    Li, Qi
    PROCEEDINGS OF 2016 4TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND INTELLIGENCE SYSTEMS (IEEE CCIS 2016), 2016, : 62 - 66
  • [38] Analysis of Privacy and Security Exposure in Mobile Dating Applications
    Patsakis, Constantinos
    Zigomitros, Athanasios
    Solanas, Agusti
    MOBILE, SECURE, AND PROGRAMMABLE NETWORKING, MSPN 2015, 2015, 9395 : 151 - 162
  • [39] National Libraries and mobile applications: analysis of online services available in Android applications
    Muriel-Torrado, Enrique
    Soares, Amanda
    REVISTA IBERO-AMERICANA DE CIENCIA DA INFORMACAO, 2020, 13 (03): : 814 - 833
  • [40] A Study of User Privacy in Android Mobile AR Apps
    Yang, Xiaoyi
    Zhang, Xueling
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,